Topic module

Logs, Endpoint, Network and Cloud Investigation

This area tests log source selection, endpoint telemetry, packet and flow analysis, cloud audit trails, evidence handling, and investigation conclusions.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

Investigations depend on collecting relevant evidence from endpoints, networks, identity providers, applications, and cloud control planes.

Exam cue: Pick the log source that can observe the event.

Concept 2

Different logs answer different questions: who, what, where, when, how, and whether the action succeeded.

Exam cue: Use timestamps, identity, source, destination, and action fields together.

Concept 3

Evidence handling requires integrity, chain of custody, scope control, and careful documentation.

Exam cue: Preserve evidence before making broad changes.

Risk pitfalls and guardrails

Using firewall logs to answer host process questions.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Changing evidence before acquisition or documentation.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Ignoring cloud audit logs for control-plane activity.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Endpoint Log

Endpoint logs show host activity such as processes, files, users, services, and detections.

Network Flow

Network flow records summarize communication metadata such as source, destination, port, protocol, and volume.

Packet Capture

Packet capture records packet-level details for deeper network analysis.

DNS Log

DNS logs show name lookups that may reveal command-and-control or phishing activity.

Authentication Log

Authentication logs show sign-in attempts, success, failure, source, and identity context.

Cloud Audit Log

Cloud audit logs record control-plane actions such as API calls, identity changes, and resource updates.

Time Synchronization

Time synchronization keeps event timestamps comparable across systems.

Chain of Custody

Chain of custody documents who handled evidence, when, how, and why.

Forensic Image

A forensic image is a preserved copy used for investigation without altering the original.

Evidence Integrity

Evidence integrity is protected through hashing, documentation, and controlled handling.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

An analyst needs to see which processes started, which files changed, and which user was active on a compromised laptop. Which source is most useful?

A company retains source IP, destination IP, ports, protocol, byte count, and session time but not payloads. What data is this?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.